A quantitative model combines a one-dimensional risk-assessment approach
with expert knowledge to enable calculation of a probability or
likelihood of exploitation of a threat to an information system asset
without referring to actuarial information. A numerical value is
established for one or more threats of attack on the information system
asset based on expert knowledge without reference to actuarial data, and
likewise, based on expert knowledge without reference to actuarial data,
a numerical value is established for each of one or more access and
privilege components of one or more vulnerabilities to attack on the
information system asset. A security risk level for the information
system asset is computed based upon the numerical values for threat and
the access and privilege components for vulnerability so established.